SSL Proxy Whitelisting for Network Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing SSL proxy systems face challenges in managing computing resources efficiently during high demand periods, leading to potential denial of access for authorized users due to insufficient resources for SSL proxy functions.

Innovation Solution

Implementing SSL proxy whitelisting, where the security device selectively performs SSL proxy functions based on available computing resources and security ratings, allowing safe data packets to bypass SSL proxy processing while ensuring high-risk packets undergo inspection, thus conserving resources and maintaining session quantity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SSL proxy functions are performed for all data packets, then security inspection coverage is improved, but computing resource consumption increases

Engineering Contradiction:
Improvesecurity inspection coverageVSAvoidcomputing resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies local quality by differentiating the level of SSL proxy inspection applied to different data packets based on their security characteristics. High-risk packets receive full SSL proxy inspection while low-risk packets receive reduced or no inspection, allowing the system to concentrate computing resources on packets that actually require security analysis rather than uniformly inspecting all traffic.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the parameter of inspection intensity based on security risk assessment. By dynamically adjusting the degree of SSL proxy function application (from full inspection to partial or no inspection) according to the security characteristics and risk level of each packet, the system optimizes computing resource utilization while maintaining appropriate security coverage.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If SSL proxy functions are selectively performed based on security ratings, then computing resources are conserved, but security inspection completeness may be reduced

Engineering Contradiction:
Improveresource efficiencyVSAvoidsecurity inspection completeness
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by assessing security characteristics and determining risk levels before applying SSL proxy functions. By pre-evaluating packets using security ratings based on characteristics like certificate validity, protocol compliance, and known vulnerability patterns, the system can make informed decisions about which packets require full inspection, avoiding unnecessary processing of safe packets while ensuring thorough inspection of suspicious ones.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If computing resources are limited, then system performance is maintained, but access denial may occur for authorized users

Engineering Contradiction:
Improvesystem performanceVSAvoiduser access availability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies local quality by providing differentiated service levels to different users based on their security risk profiles. Authorized users with low-risk characteristics experience minimal processing delays as their packets are quickly identified and routed with reduced SSL proxy inspection, while potentially malicious traffic receives more intensive scrutiny. This ensures legitimate user access is maintained while still providing security inspection where needed.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11811817B2SSL proxy whitelisting
Publication Date: 2023.11.07 JUNIPER NETWORKS INC
  • US11811817B2 patent drawing
  • US11811817B2 patent drawing
  • US11811817B2 patent drawing

AI summary

A network device may receive a first data packet. The network device may determine that a level of available computing resources satisfies a threshold level. The network device may perform a secure socket layer (SSL) proxy function based on the level of available computing resources satisfying the threshold level. The network device may receive a second data packet. The network device may determine that the level of available computing resources fails to satisfy the threshold level. The network device may determine a security characteristic associated with the second data packet. The network device may determine a security rating associated with the second data packet based on the security characteristic. The network device may selectively perform the SSL proxy function based on the security rating.